Live data from Hacker News

Chrome 69: “www.” subdomain missing from URL

bugs.chromium.org

81–90 of 919 posts

Re: Chrome 69: “www.” subdomain missing from URL

#81
post #60
post #30

This is idiotic and harmful. We already lost information about the protocol, because somebody believed it is "too complex" for users. Now we're losing other parts of the URL. It's making a joke of the SSL/TLS padlock, too — what exactly is the padlock supposed to tell me? It used to signify that a "known authority" certified that I'm connected to whatever I see in the URL bar. But now that browsers take liberties wit…

99.9% of users have no idea what any of the words you just said mean. The change was made for them, not for you (the .1%)

99.9% of motor vehicle users have no use for airbags. We still keep them for the .1%.

Re: Chrome 69: “www.” subdomain missing from URL

#83
post #47

Since everyone is wondering why, and since I happened to stumble across a reason during my time as a pentester, here you go: Spearphishing is still one of the most common ways of breaching a corporate network. If I target you, you will likely fall for one of my attempts. If you are a company rather than a person, my odds go way up, because I have N chances to trick someone rather than 1 (where N is roughly the number…

if the idea is to protect users so that you don't end up clicking on https://news.ycombinator.com.myhackerdomain.com , you then open the attack of a platform where they offer custom subdomains, and you have

https://original.blogger.com

and then

https://fake-original.blogger.com

if I make them look the same, and the address will hide the subdomain, it looks like a step backwards in securing the web

now, imagine the actual platform has a payment section, and I create a fake subdomain that looks pretty similar, email you, boom, I get your cc info because I tricked you into entering new cc info (assuming your scenario of someone being distracted)

Re: Chrome 69: “www.” subdomain missing from URL

#84

Safari has been doing this for some time. The "trivial subdomain" will show when you click the url bar, however.

I'm much more okay with Safari's implementation, because it's significantly more discoverable. Safari also makes it much simpler to disable this behavior altogether, with it earning a place in the settings ... rather than being behind some "flag" that may disappear in some future release.

Re: Chrome 69: “www.” subdomain missing from URL

#85

Looks like this is intentional. To change it back go to chrome://flags/#omnibox-ui-hide-steady-state-url-scheme-and-subdomains and disable the setting.

Thanks! This worked great for me and it brought back the https:// part as well.

Until a few releases down the line and it is decided for you that the flag should be removed.

Re: Chrome 69: “www.” subdomain missing from URL

#86
post #47

Since everyone is wondering why, and since I happened to stumble across a reason during my time as a pentester, here you go: Spearphishing is still one of the most common ways of breaching a corporate network. If I target you, you will likely fall for one of my attempts. If you are a company rather than a person, my odds go way up, because I have N chances to trick someone rather than 1 (where N is roughly the number…

Firefox fixed this by highlighting the "ycombinator.com" portion of the URL. Zero need to hide the rest from the user

I was just looking at the URL bar in firefox and thinking yea, I know it's ycombinator.com because it's right there, and there's a big green lock on the left.

Google can do what they want with Chrome, as far as I'm concerned it's the new IE.

Re: Chrome 69: “www.” subdomain missing from URL

#87
post #5

...I'm okay with this, I think. Has www (http over tcp/ip) not become the default protocol for "the internet" in the average person's mind?

I don't understand your argument, unlike "http://" the www subdomain had no real technical implication, it's just a common naming choice for web servers.

Re: Chrome 69: “www.” subdomain missing from URL

#88
post #24

This isn't entirely without precedent. Firefox does something similar by greying out the `www` in the UI, Chrome just decided to take things a step further by hiding it entirely.

Firefox's behaviour is that is makes everything except the eTLD+1 grey, because that's what's normally useful for evaluating authenticity. There's no distinction made between `www` and any other subdomain.

These are all in the same origin so they can read cookies and manipulate pages.

Re: Chrome 69: “www.” subdomain missing from URL

#89
post #60

Earlier quoted context omitted.

99.9% of users have no idea what any of the words you just said mean. The change was made for them, not for you (the .1%)

99.9% of motor vehicle users have no use for airbags. We still keep them for the .1%.

This is a very bad analogy. Anyone in a car crash potentially benefits from airbags without knowing anything about them (or even if they exist at all).

The 99.9% of people who don't even know the difference between www and non-www will never directly benefit from seeing www, ever.

Re: Chrome 69: “www.” subdomain missing from URL

#90
post #47

Since everyone is wondering why, and since I happened to stumble across a reason during my time as a pentester, here you go: Spearphishing is still one of the most common ways of breaching a corporate network. If I target you, you will likely fall for one of my attempts. If you are a company rather than a person, my odds go way up, because I have N chances to trick someone rather than 1 (where N is roughly the number…

[deleted]
Post reply on HN